FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching
Flags FortiOS sslvpnd activity containing known CVE-2022-42475 artifact paths from file-related events.
- Product
- fortios
- Service
- sslvpnd
- Author
- Nasreddine Bencherchali (Nextron Systems), Nilaa Maharjan, Douglasrose75 (SigmaHQ), DRL 1.1
- Published
- 2024-02-08
- Updated
- 2026-07-31
What it detects
This rule flags exploitation indicators for CVE-2022-42475 by matching specific file path and configuration artifact keywords observed in the sslvpnd context on FortiOS. Attackers exploiting this heap-based buffer overflow may leave behind these file or backup-related indicators, making their appearance a useful signal for compromise attempts. The detection relies on FortiOS sslvpnd telemetry that captures file creation events (or equivalent) and surfaces the referenced paths in collected logs.
Reporting behind it
- fortiguard.comhttps://www.fortiguard.com/psirt/FG-IR-22-398
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/fortinet-says-ssl-vpn-pre-auth-rce-bug-is-exploited-in-attacks/
- deepwatch.comhttps://www.deepwatch.com/labs/customer-advisory-fortios-ssl-vpn-vulnerability-cve-2022-42475-exploited-in-the-wild/
- community.fortinet.comhttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Critical-vulnerability-Protect-against-heap-based/ta-p/239420
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-42475/fortios_sslvpnd_exploit_cve_2022_42475_exploitation_indicators.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching
id: 83e495aa-d95c-4d6d-b25b-ee5cf6b2d8c2
status: test
description: This rule flags exploitation indicators for CVE-2022-42475 by matching specific file path and configuration artifact keywords observed in the sslvpnd context on FortiOS. Attackers exploiting this heap-based buffer overflow may leave behind these file or backup-related indicators, making their appearance a useful signal for compromise attempts. The detection relies on FortiOS sslvpnd telemetry that captures file creation events (or equivalent) and surfaces the referenced paths in collected logs.
references:
- https://www.fortiguard.com/psirt/FG-IR-22-398
- https://www.bleepingcomputer.com/news/security/fortinet-says-ssl-vpn-pre-auth-rce-bug-is-exploited-in-attacks/
- https://www.deepwatch.com/labs/customer-advisory-fortios-ssl-vpn-vulnerability-cve-2022-42475-exploited-in-the-wild/
- https://community.fortinet.com/t5/FortiGate/Technical-Tip-Critical-vulnerability-Protect-against-heap-based/ta-p/239420
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-42475/fortios_sslvpnd_exploit_cve_2022_42475_exploitation_indicators.yml
author: Nasreddine Bencherchali (Nextron Systems), Nilaa Maharjan, Douglasrose75, Huntrule Team
date: 2024-02-08
tags:
- attack.initial-access
- cve.2022-42475
- detection.emerging-threats
logsource:
product: fortios
service: sslvpnd
definition: "Requirements: file creation events or equivalent must be collected from the FortiOS SSL-VPN appliance in order for this detection to function correctly"
detection:
keywords:
- /data/etc/wxd.conf
- /data/lib/libgif.so
- /data/lib/libips.bak
- /data/lib/libiptcp.so
- /data/lib/libipudp.so
- /data/lib/libjepg.so
- /var/.sslvpnconfigbk
condition: keywords
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 293ccb8c-bed8-4868-8296-bef30e303b7e
type: derived